MBS Universal Gateway Flaws Threaten Building Automation Networks
ID: 6b9f6668-afcd-5d5c-89bf-5e14788ece32
STIX ID: report--6b9f6668-afcd-5d5c-89bf-5e14788ece32
Feed Name: securityonline.info
Multiple critical vulnerabilities were disclosed in MBS Universal Gateway firmware (V6_0_0_5 and earlier), including a hard-coded default password (CVE-2026-35075, CVSS 9.8) enabling unauthenticated full administrative access; three stack buffer overflow flaws (CVE-2026-35085/35084/35083, CVSS 8.8) that can lead to remote root compromise and path traversal; and input-validation/CGI bugs allowing arbitrary file deletion. Administrators are advised to immediately update affected devices to firmware V6_0_0_7 and monitor configuration files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
